Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

60,142 detections

Detects the creation of a local administrative account with a hidden naming convention (ending in $) accompanied by a cluster of registry modifications designed to obscure the account from the logon screen, enable WDigest plaintext credential caching, relax RDP authentication requirements (disable NLA, enable RDP), and disable UAC remote restrictions. This activity is highly indicative of post-exploitation persistence and credential harvesting configurations following initial access via SQL server exploitation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects a UAC bypass sequence associated with the ChainScript/Rapuncel loader, where a process invokes an 'elevation:Administrator!new' COM moniker (such as CMSTPLUA or ICMLuaUtil) followed by the execution or hollowed-out spawning of 'ServiceModelReg.exe' to achieve elevated privileges.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
004
Detects execution of an XMRig cryptominer masquerading as the legitimate system process 'smss.exe' from a non-standard file path. This detection specifically identifies the presence of the WinRing0x64.sys kernel driver, often used by XMRig for hardware MSR access, and detects preceding malicious activity involving UnRAR extraction of the miner using a specific password.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects the installation or configuration of the NvFsFilter (Alinubx.sys) persistence driver, often associated with malicious behavior that continuously terminates security software processes to allow for persistent unauthorized activity after system reboots.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
004
Detects anomalous file staging activity combined with keyword-matched file access or suspicious Steam application launches, characteristic of the Rapuncel (BoryptGrab) malware's credential and crypto-wallet harvesting routine.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
104
This rule detects the loading of the known vulnerable NvFsFilter (Alinubx) driver, followed by the abrupt cessation of multiple active AV/EDR processes within a 30-minute window. This behavior is indicative of a Bring Your Own Vulnerable Driver (BYOVD) attack, where the driver is used to execute kernel-mode commands to terminate security software, bypassing standard protection mechanisms.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
104
Detects network activity associated with the RatHat Android malware, specifically focusing on its use of WebSocket-based FRP (Fast Reverse Proxy) tunnels for command and control, session initialization, configuration retrieval, and local loopback proxy communication.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects network activity associated with the RatHat Android malware, specifically the exfiltration of accessibility tree data and calls to Google's Generative Language API (gemini-2.5-flash-lite) for UI target resolution and automation.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects the presence of known RatHat Go-based command agents (liblocal-service.so) or frpc reverse-proxy clients (libmedia_codec.so) when staged within temporary directories such as /data/local/tmp on Android devices, often following manual ADB shell interaction.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects network activity associated with the NeedyMantis malware, including TLS SNI traffic to its hard-coded C2 domain, initial beaconing over HTTPS to specific paths, and potential exfiltration or reconnaissance markers in the server's Set-Cookie header response.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects instances where the Node.js runtime process (node.exe) spawns a command shell (cmd.exe) or PowerShell (powershell.exe). This pattern is frequently used by malicious Node.js-based applications, RATs, or web shells to execute arbitrary commands on a compromised host.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
004
Detects network activity associated with the NeedyMantis malware, including TLS SNI traffic to its hard-coded C2 domain, initial beaconing over HTTPS to specific paths, and potential exfiltration or reconnaissance markers in the server's Set-Cookie header response.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects network activity associated with the RatHat Android malware agent, including C2 tasking, Go agent 'frpc' tunnel configuration retrieval, tunnel deployment status reporting, and internal loopback C2 server communication.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects network activity associated with the RatHat Android malware, specifically identifying C2 data exfiltration API calls over FRP (FRP/Go Agent) tunnels and WebSocket handshake traffic for command-and-control communication.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects instances where the Node.js runtime process (node.exe) spawns a command shell (cmd.exe) or PowerShell (powershell.exe). This pattern is frequently used by malicious Node.js-based applications, RATs, or web shells to execute arbitrary commands on a compromised host.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
14 days ago
004
Detects the RatHat post-uninstall persistence sequence on Android devices. This rule identifies a daemon that silently reinstalls an APK using 'pm install' from a temporary directory, followed by the programmatic enabling of Accessibility Service settings without user interaction.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects outbound network traffic associated with the NeedyMantis actor, specifically identifying a hardcoded outdated Firefox/21.0 User-Agent in HTTP requests attempting to upgrade to a WebSocket connection, as well as direct TLS communication with the identified C2 domain corp.tripswithengine.com.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects the execution of the 'getevent' debugging utility within an Android ADB shell context, specifically targeting raw input events from /dev/input. This behavior is indicative of potential unauthorized input monitoring, such as capturing PINs, patterns, or passwords via touch coordinate tracking.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects communication patterns associated with the RatHat Android banking trojan. The rule identifies a multi-stage C2 flow: first, the device fetches malicious overlay configurations (templates for spoofed login screens) and subsequently exfiltrates captured credentials or form data to the adversary's infrastructure via POST requests.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects RatHat Android dropper applications that utilize automated build rotation to bypass file hash-based detection. The rule identifies stable artifacts, such as specific native library names, string obfuscation indicators, and manifest structure anomalies, that persist across these regenerated builds.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000
Detects a specific Android sandbox escape technique where a malicious app enables Accessibility Services and Developer Options/Wireless Debugging to initiate a self-pairing ADB connection over localhost. This bypasses typical app sandbox restrictions, allowing the execution of processes with the UID 2000 (shell) context.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
7 days ago
000